Technologies for hardening the security of digital information on client platforms
Abstract
Technologies for hardening the security of digital information on a client device are described. In some embodiments, the client device includes a secure processing environment such as a secure enclave, which may be used to protect digital information on a client platform. The secure environment(s) may also protect assets which may be used to access the digital information. Using the secure processing environment(s), the described technologies may protect digital information as it is provided to, stored on, accessed on, and/or processed for display by a client device, even if the client device may be infested with malware or subject to attack by another entity.
Claims
exact text as granted — not AI-modified1 - 99 . (canceled)
100 . A client device, comprising: a processor; a memory having encrypted digital information stored thereon, the encrypted digital information being encrypted with a first encryption protocol; a secure processing environment having a client enterprise rights enforcement module (CEREM) and a secure video module (SVM)s stored therein; and media hardware comprising a media memory; wherein: the CEREM is to decrypt said encrypted digital information with one or more decryption keys to obtain plaintext of said digital information within said secure processing environment; said SVM is to: encrypt said plaintext of said digital information using a second encryption protocol; and transmit the digital information encrypted with said second encryption protocol to media hardware; and the media hardware is to decrypt the digital information encrypted with said second encryption protocol to obtain the plaintext of said digital information within media memory, and to encrypt said plaintext within said media memory with a third encryption protocol to produce an encrypted media signal.
101 . The client device of claim 100 , wherein said SVM is further to process said plaintext of said digital information in said secure processing environment into raw frames, to encrypt said raw frames using said second encryption protocol to produce encrypted frames, and to transmit said encrypted frames to said media hardware.
102 . The client device of claim 101 , wherein said media hardware is further to decrypt said encrypted frames to obtain said raw frames in said media memory, and to encrypt said raw frames in said media memory with said third encryption protocol to produce said encrypted media signal.
103 . The client device of claim 100 , further comprising a license sealed to said secure processing environment, the license comprising one or more decryption keys for decrypting said encrypted digital information, wherein the CEREM is to decrypt said encrypted digital information using said one or more decryption keys.
104 . The client device of claim 100 , further comprising a secure video encryption key (SVEK) sealed to or stored in said secure processing environment and said media memory, wherein:
said SVM is to use said SVEK to encrypt said plaintext of said digital information within said secure processing environment to produce SVEK encrypted digital information, and to transmit said SVEK encrypted digital information to said media hardware; and said media hardware is to use said SVEK in said media memory to decrypt said SVEK encrypted digital information, so as to obtain said plaintext of said digital information within said media memory.
105 . The client device of claim 104 , further comprising an SVEK issuing authority, the SVEK issuing authority to generate said SVEK and transmit said SVEK to said secure processing environment and said media hardware.
106 . The client device of claim 104 wherein said SVEK is a temporal SVEK.
107 . A method, comprising: decrypting encrypted digital information to obtain plaintext of said digital information within a secure processing environment of a client device, the encrypted information being stored on said client device and encrypted with a first encryption protocol; encrypting said plaintext of said digital information using a second encryption protocol; transmitting the digital information encrypted with the second encryption protocol to media hardware of said client device; decrypting the digital information encrypted with said second encryption protocol to obtain the plaintext of said digital information within a media memory of said media hardware; and encrypting said plaintext within said media memory with a third encryption protocol to produce an encrypted media signal.
108 . The method of claim 107 , further comprising:
processing said plaintext of said digital information in said secure processing environment into raw frames; encrypting said raw frames within said secure processing environment to produce encrypted frames; and transmitting said encrypted frames to said media hardware.
109 . The method of claim 108 , further comprising:
decrypting said encrypted frames with said media hardware obtain said raw frames in said media memory; and encrypting said raw frames in said media memory with said third encryption protocol to produce said encrypted media signal.
110 . The method of claim 107 , further comprising decrypting said encrypted digital information with one or more decryption keys in a license sealed to said secure processing environment, so as to obtain said plaintext of said digital information within said secure processing environment.
111 . The method of claim 107 , wherein a secure video encryption key (SVEK) is stored in said secure processing environment and said media memory, the method further comprising:
using said SVEK in said second encryption protocol to encrypt said plaintext of said digital information within said secure processing environment to produce SVEK encrypted digital information; transmitting said SVEK encrypted digital information to said media hardware; and decrypting said SVEK encrypted digital information with said media hardware using said SVEK in said media memory, so as to obtain said plaintext of said digital information within said media memory.
112 . The method of claim 111 , wherein the client device further comprises an SVEK issuing authority, the method further comprising:
generating an SVEK with said SVEK issuing authority; and transmitting said SVEK from said SVEK issuing authority to said secure processing environment and said media hardware.
113 . At least one machine readable storage medium having stored thereon, individually or in combination, instructions that when executed by at least one processor result in the following operations comprising: decrypting encrypted digital information to obtain plaintext of said digital information within a secure processing environment of a client device, the encrypted information being stored on said client device and encrypted with a first encryption protocol; encrypting said plaintext of said digital information using a second encryption protocol; transmitting the digital information encrypted with the second encryption protocol to media hardware of said client device; decrypting the digital information encrypted with said second encryption protocol to obtain the plaintext of said digital information within a media memory of said media hardware; encrypting said plaintext within said media memory with a third encryption protocol to produce an encrypted media signal.
114 . The at least one computer readable storage medium of claim 113 , wherein said instructions when executed further result in the following operations comprising:
processing said plaintext of said digital information in said secure processing environment into raw frames; encrypting said raw frames within said secure processing environment to produce encrypted frames; and transmitting said encrypted frames to said media hardware.
115 . The at least one computer readable storage medium of claim 114 , wherein said instructions when executed further result in the following operations comprising:
decrypting said encrypted frames with said media hardware obtain said raw frames in said media memory; encrypting said raw frames in said media memory with said third encryption protocol to produce said encrypted media signal.
116 . The at least one computer readable storage medium of claim 113 , wherein said instructions when executed further result in the following operations comprising:
decrypting said encrypted digital information with one or more decryption keys in a license sealed to said secure processing environment, so as to obtain said plaintext of said digital information within said secure processing environment.
117 . The at least one computer readable storage medium of claim 113 , wherein a secure video encryption key (SVEK) is stored in said secure processing environment and said media memory, wherein said instructions when executed further result in the following operations comprising:
using said SVEK in said second encryption protocol to encrypt said plaintext of said digital information within said secure processing environment to produce SVEK encrypted digital information; transmitting said SVEK encrypted digital information to said media hardware; and decrypting said SVEK encrypted digital information with said media hardware using said SVEK in said media memory, so as to obtain said plaintext of said digital information within said media memory.
118 . The at least one computer readable storage medium of claim 117 , wherein said instructions when executed further result in the following operations comprising:
generating an SVEK with said SVEK issuing authority of said client device; and transmitting said SVEK from said SVEK issuing authority to said secure processing environment and said media hardware.
119 . The at least one computer readable storage medium of claim 117 , wherein said SVEK is a temporal SVEK.Join the waitlist — get patent alerts
Track US2015304736A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.